{"id":148496,"date":"2021-01-06T17:00:34","date_gmt":"2021-01-06T14:00:34","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/how-to-use-pass-a-command-line-password-manager-for-linux-systems-cloudsavvy-it\/"},"modified":"2021-01-06T17:00:34","modified_gmt":"2021-01-06T14:00:34","slug":"how-to-use-pass-a-command-line-password-manager-for-linux-systems-cloudsavvy-it","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/how-to-use-pass-a-command-line-password-manager-for-linux-systems-cloudsavvy-it\/","title":{"rendered":"#How to Use Pass, a Command-Line Password Manager for Linux Systems \u2013 CloudSavvy IT"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6ac222d7d19b2\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #dd3333;color:#dd3333\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #dd3333;color:#dd3333\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6ac222d7d19b2\" checked aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/buradabiliyorum.com\/en\/how-to-use-pass-a-command-line-password-manager-for-linux-systems-cloudsavvy-it\/#Getting_Setup\" >Getting Setup<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/buradabiliyorum.com\/en\/how-to-use-pass-a-command-line-password-manager-for-linux-systems-cloudsavvy-it\/#Adding_Passwords_to_the_Store\" >Adding Passwords to the Store<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/buradabiliyorum.com\/en\/how-to-use-pass-a-command-line-password-manager-for-linux-systems-cloudsavvy-it\/#Retrieving_Your_Passwords\" >Retrieving Your Passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/buradabiliyorum.com\/en\/how-to-use-pass-a-command-line-password-manager-for-linux-systems-cloudsavvy-it\/#Multiline_Passwords\" >Multiline Passwords<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/buradabiliyorum.com\/en\/how-to-use-pass-a-command-line-password-manager-for-linux-systems-cloudsavvy-it\/#Git_Integration\" >Git Integration<\/a><\/li><\/ul><\/nav><\/div>\n<p><strong>&#8220;#How to Use Pass, a Command-Line Password Manager for Linux Systems \u2013 CloudSavvy IT&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8818\" src=\"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/600be55944a4d184010d63a17c6f0c43\/p\/uploads\/2021\/01\/1590ce55.jpeg\" alt=\"Image showing the pass terminal command on a dark background\" width=\"1602\" height=\"902\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>Pass is a command-line password manager built with the Unix philosophy in mind. It enables you to interact with your passwords using regular Unix commands. Credentials are stored in GPG-encrypted files.<\/p>\n<h2 id=\"getting-setup\"><span class=\"ez-toc-section\" id=\"Getting_Setup\"><\/span>Getting Setup<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><code>pass<\/code> is available within the package managers of most popular Linux distributions. Try to install it as <code>pass<\/code> using the package manager relevant to you, such as <code>apt<\/code> for Ubuntu\/Debian or <code>yum<\/code> for Fedora\/RHEL. Specific guidance for each supported distribution is available <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.passwordstore.org\/\">on the Pass website<\/a>.<\/p>\n<p>Before continuing, you\u2019ll need a GPG key available. The key will be used to encrypt the contents of your password store. You can create a new one using the following terminal command:<\/p>\n<pre>gpg --full-generate-key<\/pre>\n<p>Follow the prompts to create your key, taking care to note down its ID. You should use the default key type (RSA and RSA) but change the keysize to 4,096 bits for maximum security.<\/p>\n<p>With your GPG key available, you\u2019re now ready to initialise <code>pass<\/code>. Run the following command, substituting <code>placeholder-gpg-id<\/code> with your own GPG ID.<\/p>\n<pre>pass init placeholder-gpg-key<\/pre>\n<p>A new directory, <code>.password-store<\/code>, will be created within your home folder. Pass will store your passwords here. Each password gets its own file, making it simple to backup credentials either individually or en masse.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8819\" src=\"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/0a1333c8717be8355aed6756cd97573a\/p\/uploads\/2021\/01\/36f7bd5f.jpeg\" alt=\"Screenshot of &quot;pass init&quot; command\" width=\"912\" height=\"332\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>You can optionally use multiple password stores by setting the <code>PASSWORD_STORE_DIR<\/code> environment variable in your shell. This enables you to override the default store directory and access passwords stored in an arbitrary location.<\/p>\n<h2 id=\"adding-passwords-to-the-store\"><span class=\"ez-toc-section\" id=\"Adding_Passwords_to_the_Store\"><\/span>Adding Passwords to the Store<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Passwords are added to the store using the <code>pass insert<\/code> command. This accepts the name of the service as an argument and interactively prompts you to enter the password.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8820\" src=\"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/496c371e3f2296423f340013ac9d674c\/p\/uploads\/2021\/01\/0af8d787.jpeg\" alt=\"Screenshot of &quot;pass insert&quot; command\" width=\"900\" height=\"301\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>The password will be saved to a new encrypted file inside your store. You can create a credential hierarchy by using forward slashes in your service names. This will result in a tree of subdirectories within the password store\u2019s root.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8821\" src=\"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/1f4a57b9d011b133d26c19a2dcdf9517\/p\/uploads\/2021\/01\/9d066b14.jpeg\" alt=\"Screenshot of &quot;pass generate&quot; command\" width=\"1098\" height=\"239\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>Pass can generate new passwords for you. Use <code>pass generate<\/code>, followed by the service name and then the character length to produce. By default, a strong password consisting of alphanumeric and special characters will be created. You can prevent special characters from <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>earing using the <code>--no-symbols<\/code> (<code>-n<\/code>) flag.<\/p>\n<pre>pass generate cloudsavvy\/example-generated 32 --no-symbols<\/pre>\n<p>The command shown above will generate a new 32-character password, store it as <code>cloudsavvy\/example-generated<\/code>, and emit it to the terminal. You can have it copied to the clipboard instead by passing the <code>--clip<\/code> (<code>-c<\/code>) flag.<\/p>\n<h2 id=\"retrieving-your-passwords\"><span class=\"ez-toc-section\" id=\"Retrieving_Your_Passwords\"><\/span>Retrieving Your Passwords<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>To list the names of all your passwords, run the <code>pass<\/code> command without any arguments.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8822\" src=\"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/324244b200f1e7585cd884922aaa77fb\/p\/uploads\/2021\/01\/576c523c.jpeg\" alt=\"Screenshot of &quot;pass&quot; command\" width=\"601\" height=\"262\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>To retrieve the value of a password, supply its name as the only argument to the command.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8824\" src=\"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/db0758057344e55bb52a2b81f3aafe07\/p\/uploads\/2021\/01\/ba94a82d.jpeg\" alt=\"Screenshot of retrieving password using &quot;pass&quot;\" width=\"842\" height=\"176\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>The password will be emitted to the terminal by default. You can copy it to the clipboard instead by passing the <code>--clip<\/code> (<code>-c<\/code>) flag. Clipboard data is automatically cleared after 45 seconds to maintain security.<\/p>\n<p>Passwords are removed by passing a credential\u2019s name to <code>pass rm<\/code> (e.g. <code>pass rm cloudsavvy\/example<\/code>). Similarly, you can edit passwords using <code>pass edit<\/code>. The password\u2019s file will be opened in your default text editor.<\/p>\n<p>Any interactions with passwords will display a system prompt to unlock your GPG key. You\u2019ll need to enter your key\u2019s passphrase if it\u2019s protected. This acts as the master key protecting your entire password store.<\/p>\n<h2 id=\"multiline-passwords\"><span class=\"ez-toc-section\" id=\"Multiline_Passwords\"><\/span>Multiline Passwords<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Because passwords are just plain text files, it\u2019s possible to add multiple lines of data. This is ideal when you need to store additional security details, such as two-factor authentication recovery codes.<\/p>\n<p>Use the <code>pass edit<\/code> command to open a password file in your editor. Add additional lines to the file to attach any extra metadata you require. The actual password must remain on the first line, unprefixed, to ensure it\u2019s recognized correctly by Pass\u2019s clipboard shorthand commands.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-8823\" src=\"https:\/\/www.cloudsavvyit.com\/thumbcache\/0\/0\/e47d276329803ef6ac15d70a6c09b128\/p\/uploads\/2021\/01\/1eb812dd.jpeg\" alt=\"Screenshot of &quot;pass insert&quot; command with multiline option\" width=\"934\" height=\"211\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>You can save time when creating passwords by passing the <code>--multiline<\/code> (<code>-m<\/code>) option to the <code>pass insert<\/code> command. This will enable you to enter multiple lines into your terminal. Press Ctrl+D when done to save the credentials into your store.<\/p>\n<h2 id=\"git-integration\"><span class=\"ez-toc-section\" id=\"Git_Integration\"><\/span>Git Integration<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Pass has built-in support for Git. This enables you to version control your passwords and provides a simple mechanism to keep data synchronised across machines. Run <code>pass git init<\/code> to add Git to your password store.<\/p>\n<p>You can now use Pass as normal. A Git commit will be created each time a password is added, changed, or removed. You can interact with the Git repository by using regular Git commands, prefixed by <code>pass git<\/code>:<\/p>\n<pre>pass git remote add origin example-server:\/passwords.git&#13;\npass git push -u origin master<\/pre>\n<p>The previous command adds a remote Git repository to your password store. You can then <code>git push<\/code> your passwords into it, giving you a backup in case you lose access to your current machine.<\/p>\n<p>Pass is an intentionally minimal solution. It\u2019s much simpler than most graphical password managers, favoring a file-based approach that aligns with Unix principles. A strong ecosystem of third-party projects supports the Pass core, enabling integration with other apps and operating systems.<\/p>\n<p>Data importers are available for most popular password managers, including 1Password, Keepass, and Lastpass. Compatible client apps are available for <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/github.com\/zeapo\/Android-Password-Store#readme\">Android<\/a>, <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/mssun.github.io\/passforios\/\">iOS<\/a> and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/github.com\/mbos\/Pass4Win#readme\">Windows<\/a>. <code>dmenu<\/code> users can utilize the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/git.zx2c4.com\/password-store\/tree\/contrib\/dmenu\/README.md\"><code>passmenu<\/code> script<\/a> to rapidly search and select passwords without opening a terminal window.<\/p>\n<p>The <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.passwordstore.org\/\">Pass website<\/a> lists many notable community projects that extend the tool\u2019s functionality and enable data portability to other platforms. You can obtain further guidance on using Pass itself from its manual page, accessed by running <code>man pass<\/code> in a terminal.\n<\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.cloudsavvyit.com\/8817\/how-to-use-pass-a-command-line-password-manager-for-linux-systems\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#How to Use Pass, a Command-Line Password Manager for Linux Systems \u2013 CloudSavvy IT&#8221; Pass is a command-line password manager built with the Unix philosophy in mind. It enables you to interact with your passwords using regular Unix commands. Credentials are stored in GPG-encrypted files. Getting Setup pass is available within the package managers of&#8230;<\/p>\n","protected":false},"author":1,"featured_media":148497,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.cloudsavvyit.com\/p\/uploads\/2021\/01\/1590ce55.jpeg","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-148496","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/148496","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=148496"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/148496\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/148497"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=148496"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=148496"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=148496"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}